Trojan

Trojan.MalPack.EnigmaProtector removal

Malware Removal

The Trojan.MalPack.EnigmaProtector is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MalPack.EnigmaProtector virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics

How to determine Trojan.MalPack.EnigmaProtector?


File Info:

name: 0BBFC30A6F083F9BB297.mlw
path: /opt/CAPEv2/storage/binaries/191141214a9958205a3c833399d2f882a8a664899e3c2c2d1a3d44d5fc35c93a
crc32: B83BC2A9
md5: 0bbfc30a6f083f9bb297a0da8943f1e6
sha1: 6e6e28e409f22a4e49ca4d7e4043746c51c16bf7
sha256: 191141214a9958205a3c833399d2f882a8a664899e3c2c2d1a3d44d5fc35c93a
sha512: a8f0ec28e5dffa4702c23739f50d99c149213a5d7f95d144940441465afb70c4311f85fe928fbdeab1f04b44635b2a690fa4b9f8d25ad46fdf97142d36ea586f
ssdeep: 24576:Rtq7NXN+HV6G/V9YzGhlP4AtAMrp+Q+dyC2fihxLzRrjh:RtG90PtKShlPV30dyC22Jz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B4533A7AC77A0A1C5DA70FE98CB597F025B0EB194CA718F506276272B57083D0B730E
sha3_384: 74c70a8a55a3ca9e2622fa7287574e7a34364afe3a010dcf5be923710309062940867a79f38800a91dbaafc20f761a4f
ep_bytes: eb0800a603000000000060e800000000
timestamp: 2022-10-28 02:34:40

Version Info:

0: [No Data]

Trojan.MalPack.EnigmaProtector also known as:

BkavW32.AIDetect.malware1
LionicTrojan.MSIL.Quasar.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.92005
FireEyeGeneric.mg.0bbfc30a6f083f9b
ALYacGen:Variant.Babar.92005
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052a8371 )
AlibabaBackdoor:Win32/Bladabindi.9a505cb7
K7GWTrojan ( 0052a8371 )
Cybereasonmalicious.409f22
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.MSIL.Bladabindi.bwyp
BitDefenderGen:Variant.Babar.92005
NANO-AntivirusTrojan.Win32.Bladabindi.jtiige
AvastWin32:Malware-gen
TencentMsil.Backdoor.Bladabindi.Pjgl
Ad-AwareGen:Variant.Babar.92005
EmsisoftGen:Variant.Babar.92005 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Babar.92005
TrendMicroTROJ_GEN.R002C0PJS22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Enigma
GDataGen:Variant.Babar.92005
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Packed]/Win32.EnigmaProtector
ArcabitTrojan.Babar.D16765
ViRobotTrojan.Win32.Z.Babar.1223168
ZoneAlarmBackdoor.MSIL.Bladabindi.bwyp
MicrosoftTrojan:Win32/Tiggre!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.R266308
Acronissuspicious
McAfeeArtemis!0BBFC30A6F08
VBA32TrojanDropper.Convagent
MalwarebytesTrojan.MalPack.EnigmaProtector
TrendMicro-HouseCallTROJ_GEN.R002C0PJS22
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
YandexRiskware.EnigmaProtector!9UBC3FVZUPM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.34796.krW@aix76Hn
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.MalPack.EnigmaProtector?

Trojan.MalPack.EnigmaProtector removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment